alliance-prioritization
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze data from external, potentially untrusted sources such as customer reports, marketplace directories, and web search results to perform alliance ranking.
- Ingestion points:
SKILL.mdWorkflow Step 1 and Step 17 direct the agent to gather data from external reports and to "verify each candidate's current state" using web browsing. - Boundary markers: The instructions do not prescribe specific delimiters or boundary markers to isolate external data from the system prompt or agent instructions.
- Capability inventory: No critical or high-risk capabilities such as arbitrary command execution, shell access, or system file modification were detected.
- Sanitization: There are no requirements in the skill to sanitize or escape retrieved external content before it is processed by the model.
Audit Metadata